[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH] xen/arm: Sanity test specified domain's memory for being a multiple of a page size


  • To: <xen-devel@xxxxxxxxxxxxxxxxxxxx>
  • From: Michal Orzel <michal.orzel@xxxxxxx>
  • Date: Wed, 7 Oct 2026 14:48:13 +0200
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 165.204.84.17) smtp.rcpttodomain=lists.xenproject.org smtp.mailfrom=amd.com; dmarc=pass (p=quarantine sp=quarantine pct=100) action=none header.from=amd.com; dkim=none (message not signed); arc=none (0)
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=HUJVRizNZmdEf6Vn70Frllzcj4hzPR8FEdALiHfbpog=; b=MnV9rdlYsZ5gKCZbU5GKda1m/oXMeCoyBva2F5+20sqxZVSVMZ2zqeZ8nSnhA0z89WXIZiZd7agzH4X3QZi6de5gHqlqwo3qStPGg+X+cOtXBBsE4CFmI+8ViWx+lU5VDm6vnTIbayL9z2Fcd6UIAL4r88WpdlzVBpmSRIW0mpOl1FlSn5wr+N6sqXODOM3c1NrlMi9i5bRJ0IZ1bVreMIT5iybM3NSURYEuFVc5/VYRY85svodRVFQjUrCZxLEVakr81FOr3XwR6uy8o9O0P9DdVTC42SEfODoSpmESbrDYusbflT9qQ7hcJtj3aMRx0JWV6plG5yQh4g7gWTD6BQ==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=HT3gxFmMQdGku+BGnvWjndBQJPaiAplA6qzvtG3uPfg469CX/9tqg1jHTI9h1aaxYYA6qkDzlsTq6F3Oxqewad2STaYJp9IuOQIcpLRM05ru6iJDiW0s/P+Htk8vz+PrI2rnfv24MMa0SGwvAt5d2CNr7zifxaBe0ZXqO3+jyesYnGT5KdX0jW9MHb1yRhQBTo3OKVoV0ypWwMcBR/F1CUZWcnGnQuJeovHkD0Z228ORAydEl/YkGo+UGlQYrM0DQHXpzCgL3OM6PyCNnTkBSB6zQd4B9iJCm7DhZYn4KOJ23WOS7nG/vTZaj52PGjaXcOvWobpiH1xFQ6zn4yrXsQ==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=amd.com header.i="@amd.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
  • Cc: Michal Orzel <michal.orzel@xxxxxxx>, Stefano Stabellini <sstabellini@xxxxxxxxxx>, Julien Grall <julien@xxxxxxx>, Bertrand Marquis <bertrand.marquis@xxxxxxx>, Volodymyr Babchuk <Volodymyr_Babchuk@xxxxxxxx>, Andrew Cooper <andrew.cooper3@xxxxxxxxxx>, Anthony PERARD <anthony.perard@xxxxxxxxxx>, Jan Beulich <jbeulich@xxxxxxxx>, Roger Pau Monné <roger@xxxxxxxxxxxxxx>
  • Delivery-date: Wed, 07 Oct 2026 12:48:54 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>

We require memory to allocate for a domain as RAM to be a multiple of a
page size. However, we neither document this nor sanity test. Specifying
memory size that does not conform to this requirement fails the domain
memory allocation in the non-obvious way that is difficult to parse for
the user (printing over-allocation messages followed by the panic that Xen
could not allocate the requested amount of memory).

While there, fix indentation from tabs to spaces for "memory" parameter in
booting.txt.

Signed-off-by: Michal Orzel <michal.orzel@xxxxxxx>
---
 docs/misc/arm/device-tree/booting.txt   | 4 ++--
 docs/misc/xen-command-line.pandoc       | 5 +++--
 xen/arch/arm/domain_build.c             | 6 ++++++
 xen/common/device-tree/dom0less-build.c | 7 +++++++
 4 files changed, 18 insertions(+), 4 deletions(-)

diff --git a/docs/misc/arm/device-tree/booting.txt 
b/docs/misc/arm/device-tree/booting.txt
index bcb06bc796bf..7dfac2062a37 100644
--- a/docs/misc/arm/device-tree/booting.txt
+++ b/docs/misc/arm/device-tree/booting.txt
@@ -155,8 +155,8 @@ with the following properties:
 
 - memory
 
-       A 64-bit integer specifying the amount of kilobytes of RAM to
-    allocate to the guest.
+    A 64-bit integer specifying the amount of kilobytes of RAM to
+    allocate to the guest. Must be a multiple of 4KB (the page size).
 
 - cpus
 
diff --git a/docs/misc/xen-command-line.pandoc 
b/docs/misc/xen-command-line.pandoc
index ea0e3368b1d6..d49db353d8a8 100644
--- a/docs/misc/xen-command-line.pandoc
+++ b/docs/misc/xen-command-line.pandoc
@@ -1020,8 +1020,9 @@ and architecture-specific domain limits.
 > `= <size>`
 
 Set the amount of memory for the initial domain (dom0). It must be
-greater than zero. This parameter is required (and only used) when the initial
-domain is not described in the Device-Tree.
+greater than zero and a multiple of the page size (4KB). This parameter is
+required (and only used) when the initial domain is not described in the
+Device-Tree.
 
 ### dom0_mem (x86)
 > `= List of ( min:<sz> | max:<sz> | <sz> )`
diff --git a/xen/arch/arm/domain_build.c b/xen/arch/arm/domain_build.c
index 72d531618045..bc3d1ebad1c4 100644
--- a/xen/arch/arm/domain_build.c
+++ b/xen/arch/arm/domain_build.c
@@ -1881,6 +1881,12 @@ static int __init construct_dom0(struct domain *d)
         warning_add("PLEASE SPECIFY dom0_mem PARAMETER - USING 512M FOR 
NOW\n");
         dom0_mem = MB(512);
     }
+    else if ( dom0_mem % PAGE_SIZE )
+    {
+        printk("%pd: specified dom0_mem (%"PRIu64"B) is not a multiple of a 
page size\n",
+               d, dom0_mem);
+        return -EINVAL;
+    }
 
     d->max_pages = dom0_mem >> PAGE_SHIFT;
 
diff --git a/xen/common/device-tree/dom0less-build.c 
b/xen/common/device-tree/dom0less-build.c
index fcbeb8adbd73..b3f24e5d555f 100644
--- a/xen/common/device-tree/dom0less-build.c
+++ b/xen/common/device-tree/dom0less-build.c
@@ -789,6 +789,13 @@ static int __init construct_domU(struct kernel_info *kinfo,
     }
     kinfo->unassigned_mem = (paddr_t)mem * SZ_1K;
 
+    if ( kinfo->unassigned_mem % PAGE_SIZE )
+    {
+        printk("%pd: specified \"memory\" (%"PRIu64"KB) is not a multiple of a 
page size\n",
+               d, mem);
+        return -EINVAL;
+    }
+
     rc = domain_p2m_set_allocation(d, mem, node);
     if ( rc != 0 )
         return rc;
-- 
2.43.0




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.